If your USDT has been frozen, the decision about what happens next was almost certainly not made by a person at Tether reading your transaction history. It was made by software. Blockchain analytics companies scan public chains continuously, score addresses for risk, and hand exchanges, issuers and investigators the output. Understanding what that software actually looks at explains a lot about why wallets get frozen, why freezes spread to addresses you never touched directly, and what evidence actually moves the needle when you ask for a release.
Who builds the screening tools
Two companies dominate the screening market: Chainalysis and TRM Labs. Both maintain indexed copies of major blockchains and label addresses by associating them with known entities: exchanges, mixers, darknet markets, ransomware operators, sanctioned parties, scam infrastructure. Elliptic plays the same role, and smaller firms including Merkle Science and Crystal (operated by Bitfury) compete for the same contracts. When a bank, an exchange, or a law-enforcement agency wants to know whether an address is tainted, they usually query one of these systems.
It matters that these are private companies selling subscriptions. There is no court behind a risk score. A label applied once, sometimes from a single news report or an unverified cluster attribution, propagates into every downstream compliance decision. Getting a label corrected means convincing the analytics firm itself, not a judge.
What a risk score is built from
Screening engines do not read your emails or know your intentions. They work from the graph of transactions. The typical inputs:
- Direct exposure. Funds that came to your address straight from a labelled entity, for example a mixer withdrawal or a payment from a sanctioned address.
- Indirect exposure. Funds that passed through a labelled address a few hops before reaching you. Most engines measure this by percentage of balance over a set hop depth, commonly one to five hops.
- Sanctions lists. OFAC’s SDN list includes specific blockchain addresses, a practice that started with individual Bitcoin addresses in 2018 and expanded to smart contracts, most famously the Tornado Cash mixing protocol in 2022. An address that has interacted with a sanctioned contract can inherit a severe score even if the interaction was tiny or unknowing.
- Behavioural clustering. Heuristics that group addresses likely controlled by the same entity: common spend patterns, timing, peeling chains, service-wide wallet reuse. Your address can land in a cluster you have no relationship to if the heuristic misfires.
- Counterparty risk. If the people who pay you, or the people they were paid by, are flagged, your own score degrades.
The output is usually a percentage figure per category, for example “12 percent indirect exposure to darknet market over three hops”, plus a band: low, medium, severe. Compliance teams at exchanges act on bands, not nuance. A severe band generally means the account is frozen and the file is escalated, whatever the underlying percentage says.
Why freezes hit people who did nothing wrong
The mixer problem explains most innocent-victim cases. Tornado Cash on Ethereum processed enormous legitimate volume alongside criminal volume, because it was cheap and worked well. After the 2022 sanctions designation, any address with mixer-tainted USDT downstream became toxic to screeners. People who had withdrawn from the mixer years earlier, sometimes amounts in the hundreds of dollars, found exchange accounts closed and funds held. The Fifth Circuit’s 2024 ruling in the Van Loon case found that immutable smart contracts are not “property” that can be sanctioned, and OFAC subsequently delisted Tornado Cash in 2025, but analytics labels lag behind delisting, and some downstream exposure scores still treat historical mixer contact as a red flag.
The second common path is receiving stolen funds. If a payment you accepted traces back to a reported hack or a pig-butchering scam, your address inherits that exposure the moment the USDT lands. You do not need to have known. The freeze request to Tether typically follows once the victim reports the theft and an exchange or investigator traces the flow to your address.
What this means for a release request
Because the freeze rests on a chain-derived risk narrative, the evidence that helps you is evidence that breaks the narrative. That means:
- Proof of the legitimate origin of your funds. Withdrawal records from a licensed exchange, dated and tied to the exact deposit transaction hash. This is the single most useful document, because it gives the reviewer a verified alternative story for where the money came from.
- The transaction trail with hashes. Every hop into and out of your address that you can account for, with txids. Reviewers will check them against their own graph; the ones you cannot explain are the ones they will weigh against you.
- Context for the flagged transaction. If you sold goods, show the invoice or the marketplace listing and the chat. If you were paid by an employer, show the contract. An unexplained inflow from a stranger is treated as it looks.
- Identity documents that let the reviewer confirm you are a real, traceable person and not a mule in someone else’s laundering chain.
What does not help: asserting that you are innocent, threatening litigation before establishing the facts, or sending thousands of screenshots with no transaction hashes. Reviewers work hash-first.
Practical hygiene before anything goes wrong
Keep USDT you care about in addresses whose history you can fully document. Withdraw from named exchanges to a dedicated receiving address you do not reuse. Do not accept significant payments from strangers directly into a holding wallet; use a fresh address per counterparty so one tainted inflow does not contaminate the balance. If you have ever used a mixer, accept that this will surface in any serious compliance review and prepare the documentation before you need it, not after.
Screening is not going away. Exchanges are obligated to run it, and Tether’s own freezes, thousands of addresses and billions of dollars’ worth, exist largely in response to law-enforcement requests built on these analytics. The system is blunt and occasionally wrong. The people who get unfrozen fastest are the ones who understood what the machine was looking at and answered it in its own language.